Risk Treatment Plan¶
Purpose. Turns the Risk Assessment Report (ISMS-DOC-06-3) into tracked, owned actions with due dates (ISO/IEC 27001 6.1.3, 8.3). Per the acceptance criteria: ๐ด High (10โ25) must be treated; ๐ก Medium (5โ9) is treated where proportionate with the decision documented; ๐ข Low (1โ4) is retained.
1. Scope¶
All risks in the Risk Assessment Report at or above the treatment threshold. Status is updated in the weekly ISMS sync; the plan is formally reviewed at management review and at least annually. Risk owners approve this plan and accept the residual risks (6.1.3 f/g) โ recorded at management review.
2. Treatment actions โ ๐ด High risks (must treat)¶
Ordered by initial risk level. โก = quick win. All due dates are
TODO(owner): set at the 2026-07-24 sync.
| Risk | Initial | Action(s) | Action owner | Due | Status | Target residual |
|---|---|---|---|---|---|---|
| R-01 BYOD endpoint loss/malware | ๐ด 16 | Enforce disk encryption + screen lock + auto-updates on all devices per Device Management Policy; decide MDM tooling (see R-02) | TODO(owner) | TODO | Open | ๐ก 8 |
| R-21 Product feature abused for brand-impersonation phishing (confirmed 2026-07-02) | ๐ด 16 | Rate-limit/moderate free-text invitation message + logo upload for new/unverified accounts; content validation; impersonation detection | TODO(owner): product/eng | TODO | Open | ๐ก 6 |
| R-05 Secrets/keys leaked | ๐ด 15 | Move remaining plaintext secrets (devops/cfg, frontend .env โ Q1 hygiene item) to a secrets manager and rotate; keep Aikido secret scanning on | TODO(owner) | TODO | Open | ๐ก 6 |
| R-15 Backup failure / cannot restore (confirmed 2026-07-04) | ๐ด 15 | Enable PITR on both RDS instances; extend rds-soon-soon-prd retention beyond 7d; run and record first restore drill (M8); copy snapshots to isolated account/region (immutable where possible); correct customer-facing Security Overview |
Melvin Jacobson | TODO | Open | ๐ข 4 |
| R-02 No central endpoint management | ๐ด 12 | Decide: MDM tooling or documented hardening baseline + annual attestation; implement chosen option | TODO(owner): Thomas proposes at sync | TODO | Open | ๐ก 6 |
| R-03 Credential compromise on SaaS lacking SSO/MFA (GitHub MFA on honour system, confirmed 2026-07-04) | ๐ด 12 | โก Enable GitHub org-wide MFA enforcement setting; roll out WorkOS SSO to remaining feasible tools; maintain non-SSO list | TODO(owner): GitHub org admin | TODO | Open | ๐ข 4 |
| R-08 Intercom US-hosted โ EU-residency breach (confirmed 2026-07-03) | ๐ด 12 | Migrate to Intercom EU data hosting or replace (Linear S-303); verify remaining sub-processors; reconcile Security Overview | Olaf Jacobson | TODO | In progress (S-303) | ๐ก 6 |
| R-09 Staging shares production RDS host | ๐ด 12 | Verify what "different state" means; confirm whether real customer data reaches staging; mask/synthesize or separate if so | Thomas Picauly | TODO | Open | ๐ข 4 |
| R-12 Cloud misconfiguration | ๐ด 12 | IaC review in PRs; config baselines; keep Aikido cloud scanning on | TODO(owner) | TODO | Open | ๐ก 6 |
| R-13 Unpatched dependencies/images | ๐ด 12 | Dependency scanning (Aikido) with patch SLAs (proposal: critical 7d / high 30d โ confirm); schedule first pentest | TODO(owner) | TODO | Open | ๐ก 6 |
| R-14 Production outage | ๐ด 12 | Confirm/implement AWS multi-AZ; alerting via CloudWatch; write ops runbooks; draft Business/ICT Continuity Plan (A.5.29/30 gap) | TODO(owner): Thomas | TODO | Open | ๐ก 6 |
| R-16 No formal incident response | ๐ด 12 | โก Approve the now-written Incident Response Procedure + Breach Notification Procedure; run a tabletop exercise | Olaf Jacobson | TODO | Partially done (documents drafted) | ๐ข 4 |
| R-19 Phishing of remote staff | ๐ด 12 | Awareness training via /isms:onboard for whole team (log in Training Log); MFA per tiered posture; reporting culture per Event Reporting Procedure |
Olaf Jacobson | TODO | Open | ๐ก 6 |
| R-22 No native product MFA for customer email/password accounts (confirmed 2026-07-03) | ๐ด 12 | Add native MFA to product roadmap with target date; interim: encourage SSO adoption for higher-risk customers; correct Security Overview | Thomas Picauly | TODO | Open | ๐ก 6 |
| R-23 Customer data to LLM providers without confirmed DPAs (Q8) | ๐ด 12 | Map which customer data reaches OpenAI/Anthropic/Mistral/Deepseek/X.AI; obtain/verify DPAs + zero-retention/EU terms; drop non-compliant providers; update sub-processor list | Thomas Picauly | TODO | Open | ๐ก 6 |
| R-04 Over-provisioned privileged cloud access | ๐ด 10 | โก Run first quarterly privileged access review per Access Control Policy ยง2.4; least-privilege cleanup | TODO(owner) | TODO | Open | ๐ข 4 |
| R-07 Customer PII breach (processor) | ๐ด 10 | Composite risk โ reduced by R-05/08/09/15/16 actions plus encryption and access control; verify DPA/breach-notification chain end-to-end once IR procedures approved | Olaf Jacobson | TODO | Open | ๐ก 5 |
3. ๐ก Medium risks โ decision required (treat or retain, document either way)¶
| Risk | Initial | Proposed handling | Decision (TODO(owner): record at sync) |
|---|---|---|---|
| R-06 Data exposure via AI tools | ๐ก 9 | Treat lightly: AI-use rules already in Acceptable Use Policy; confirm approved-tools list | TODO |
| R-11 Suppliers without DPA/assessment | ๐ก 9 | Treat: complete supplier register + due-diligence per Supplier policy | TODO |
| R-17 Key-person dependency | ๐ก 9 | Treat lightly: runbooks (with R-14), cross-training | TODO |
| R-20 Logging/monitoring gaps | ๐ก 9 | Treat lightly: confirm alerting coverage per Logging & Monitoring Policy | TODO |
| R-10 Sub-processor breach | ๐ก 8 | Partly shared (DPAs); monitor โ proposal: retain at current level | TODO |
| R-18 Leaver access not revoked | ๐ก 8 | Treat lightly: adopt Termination Checklist as standard; covered by same-day revocation rule | TODO |
4. Roles & responsibilities¶
- Risk owners (per 06-3) โ approve treatment for their risks and accept residual risk at management review.
- Action owners (table above) โ deliver actions by the due date; attach proof.
- Olaf Jacobson (ISM, plan owner) โ tracks status in the weekly sync, escalates slipping actions, brings the plan to management review.
5. Related documents¶
- Risk Assessment and Treatment Process โ methodology & criteria
- Risk Assessment Report โ the register this plan derives from
- Statement of Applicability โ control mapping must stay consistent with these actions
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | โ | โ | CertiKit template (empty table) |
| 0.2 | 2026-07-20 | Andrea Cardinali | Generated from Risk Assessment Report v0.4: 17 High risks with actions/owners where confirmed, 6 Medium risks pending treat/retain decision; due dates and remaining owners to be set at the 2026-07-24 sync |